Home › About › Certifications

Certifiable by design.
Compliant from
day one.

WakaStart doesn't bolt compliance on after development. It's built into the code from the moment it's generated. Every SaaS delivered natively embeds ISO 27001, NIS2, GDPR, HDS and eIDAS rules — with no separate compliance project and no extra budget.

ISO 27001Natively ready
NIS2Zero Trust built in
HDSHealth data
eIDAS 2.0Qualified signature

Certifications & Compliance

Every rule natively embedded in your SaaS through Cybercoding

ISO 27001

Natively ready

NIS2

Zero Trust native

HDS

Health data

eIDAS 2.0

Qualified signature

GDPR

Native & CNIL

Digital vault

WORM · Evidential

OVH France

100% sovereign

Post-quantum

ML-DSA · ML-KEM

ISO 27001 — Information Security Management System

ISO 27001-ready.
Not ISO 27001
as an afterthought.

ISMS rules natively embedded in every build

WakaStart does not certify your SaaS — this certification is issued by an accredited external COFRAC auditor. What WakaStart does is deliver software where every line of code already meets the requirements of the ISO 27001 standard. The result: the certification audit that follows takes a few weeks instead of 18 months.

Complete technical documentation — SSP, QAP, BCP, DRP generated automatically
Immutable WORM audit logs — full traceability of every event
Risk management — documented RBAC matrix, least-privilege policy
SAST/DAST report — zero critical vulnerabilities allowed in production
4 ISO-mirrored environments — Dev / Staging / UAT / Production strictly isolated
Important: WakaStart natively embeds ISO 27001 rules into your SaaS. Official certification is issued by an external COFRAC auditor. WakaStart provides you with the complete file to facilitate and speed up this audit.

ISO 27001 compliance report

Audit-ready
Security policyDocumented
Risk analysisComplete
Critical vulnerabilities (SAST/DAST)0 detected
OWASP Top 10 controlsAll covered
SSP · QAP · BCP · DRPAuto-generated
Immutable audit logsWORM active
COFRAC auditor fileReady to submit
NIS2 — European Network Security Directive

NIS2 native.
Zero Trust
from generation.

Built-in NIS2 compliance — 2027 deadline

The NIS2 directive requires B2B digital service providers to meet strict requirements for risk management, business continuity and incident traceability. WakaStart natively implements Zero Trust architecture, multi-datacentre geo-redundancy and the incident notification mechanisms required by NIS2.

Zero Trust architecture — systematic verification on every request, no implicit access
OVH France multi-datacentre geo-redundancy — guaranteed HA, ongoing NIS2 continuity compliance
Incident notification — automated SIEM alert escalation pipeline
Secure supply chain — ML-DSA signature on every build
No manual handling required — systematically applied across the entire CI/CD pipeline

NIS2 Zero Trust architecture

Compliant
JWT verification on every requestActive
Application WAFActive
Datacentre geo-redundancy2 FR zones
RTO / RPO< 4h / < 1h
SIEM & incident alertsReal time
ML-DSA build signaturePost-quantum
HDS — Health Data Hosting

Health data.
Legal compliance.
Native.

A legal requirement for any SaaS processing personal health data

In France, hosting or processing personal health data without HDS certification is a criminal offence. WakaStart relies on OVH's HDS-certified infrastructure to guarantee full legal compliance — strict partitioning of medical data, ANS-specific audit logs, compliant hosting contracts.

HDS-certified OVH infrastructure — legally compliant hosting with no separate project
RLS partitioning by patient and by facility — physical and logical isolation
Automatic pseudonymisation of sensitive medical data
Health data access audit logs — compliant with CNIL and ANS
HDS contracts and certification file provided for ANS calls for tender
Compatible with Mon Espace Santé — ANS connectors available via WAKA-HDS

HDS compliance — Health data

Compliant
HDS-certified OVHDedicated infrastructure
Health data partitioningNative RLS
PseudonymisationAutomatic
HDS contractsProvided
Mon Espace Santé connectorAvailable
ISO 27001 prerequisiteIncluded
eIDAS 2.0 — European Electronic Signature

Qualified signature.
Legal value
in 27 countries.

The eIDAS 2.0 regulation and the EUDI Wallet

Via the WAKA-SIGN module, your SaaS natively integrates qualified electronic signature (QES) — the highest level recognised under the European eIDAS 2.0 regulation. Your contracts, quotes and documents carry full legal value across all 27 EU member states, with no need for an external provider.

QES — maximum eIDAS level, legal value across Europe
EUDI Wallet ready — compatible with the European digital identity wallet
Qualified timestamping (QTS) — legally certified proof of anteriority
Configurable multi-signatory workflow — built-in validation flows
10-year evidential archiving — integrated digital vault

WAKA-SIGN — eIDAS 2.0

Active
Signature levelQES — Max
Legal scope27 EU states
EUDI WalletCompatible
Qualified timestampingQTS built in
Evidential archiving10 legal years
Audit trailComplete
GDPR — General Data Protection Regulation

GDPR native.
Not a box
to tick.

CNIL compliance built in from code generation

GDPR imposes precise technical obligations: data minimisation, traceable consent, right to erasure, records of processing activities. WakaStart natively generates all of these mechanisms in your SaaS — including consent forms, CNIL audit logs and data reversibility procedures.

Records of processing activities — automatically generated and maintained
CNIL consent forms — granular management by data type
Right to be forgotten — deletion/anonymisation procedure per user
Data portability — structured export on user request
Native multi-tenant partitioning — no cross-customer data leakage possible
Built-in DPO role — dedicated access profile for the data protection auditor
gdpr.config.ts
1// Automatically generated by Cybercoding
2export const gdprConfig = {
3  consent: {
4    granular: true,
5    auditLog: 'immutable',
6  },
7  rightToErasure: 'automated',
8  portability: 'JSON/CSV',
9  processingRegister: 'auto-generated',
10  tenantPartitioning: 'strict RLS',
11  dpoRole: 'dedicated access'
12}
Digital Vault & Evidential Archiving

Immutable.
Tamper-proof.
Evidential.

WORM Object Lock · Blockchain · SHA-256 · Legal value

Via WAKA-SEAL, every archived document is cryptographically sealed, timestamped and stored in WORM (Write Once, Read Many) mode. Not even a root administrator can modify or delete an archive. The cryptographic block chaining guarantees that any tampering attempt immediately breaks the chain and triggers an alert.

WORM Object Lock compliance — no modification possible, even by root
SHA-256 hash chaining — any tampering breaks the chain and triggers a real-time alert
Blockchain anchoring — tamper-proof distributed timestamping for legal anteriority
Post-quantum ML-DSA signature — resistant to future quantum computers
Instant forensic report — ready for ISO 27001 audit or legal proceedings

WAKA-SEAL — Evidential archiving

Active
Storage modeWORM compliance
Hash algorithmSHA-256
TimestampingBlockchain
SignatureML-DSA PQC
Tampering possible0 — impossible
Forensic report1 click
AES-256Encryption at rest & in transit
TLS 1.3PFS — No-downgrade policy
ML-DSAPost-quantum signature
0Critical vulnerability allowed in production

Infrastructure & Encryption

What protects your SaaS
under the hood.

Every security component is configured, tested and documented by our CISOs — not left to the discretion of a developer coding on a Friday evening.

Keycloak IAM — Identities & Access

Centralised identity management, SSO (Google, Microsoft, Apple, AD, SAML, OIDC), MFA, 3-tier multi-tenant RBAC. No implicit access — every permission is explicitly defined.

RBAC · ABAC · JWT

Vault — Secrets & Credentials

Encrypted storage of all secrets (API keys, database credentials, tokens). Automatic rotation, role-based access, strict Dev/Staging/Production isolation. No hard-coded secrets in the code.

Zero Secrets · Auto rotation

SIEM — Real-time monitoring

Centralised logging with OpenTelemetry, Prometheus, Grafana. Real-time alerts on intrusion attempts, authentication errors and abnormal behaviour. Dedicated Auditor role.

OpenTelemetry · Grafana

WAF & Antivirus

Application firewall active on all instances. Mandatory antivirus scanning on all uploaded files. Protection against OWASP Top 10 attacks, DDoS, SQL injection, XSS.

WAF · OWASP · Antivirus

SAST/DAST — Automated scans

Static and dynamic analysis on every build. Zero critical vulnerabilities allowed in production — the pipeline is blocked until the report is clean. CVEs on all dependencies checked continuously.

SAST · DAST · CVE

Encrypted backups

Automated backups twice daily, AES-256 encryption, triple-redundant storage across 3 OVH France geographic zones, monthly restore testing. RPO < 1h, RTO < 4h.

AES-256 · Triple redundancy

Your questions

What CISOs and buyers
ask us most often.

Does WakaStart produce SaaS ready for ISO 27001 certification?

WakaStart natively embeds the requirements of the ISO 27001 standard into every SaaS it delivers. Official certification is issued by an accredited external COFRAC auditor — not by WakaStart. What WakaStart does is deliver software whose architecture, documentation and controls are already compliant with the standard, so the certification audit that follows is fast, predictable and free of surprises.

Where is my customers' data hosted?

100% in France, on OVH infrastructure. Two datacentres in France in active geo-redundancy. No data ever transits to servers outside the EU. For HDS projects (health data), hosting takes place on OVH's specifically HDS-certified infrastructure. For customers requiring maximum isolation, on-premise Runtime mode runs the application within your own infrastructure.

How does multi-tenant partitioning work?

Cybercoding applies native Row-Level Security (RLS) at the PostgreSQL database level. Every request is intercepted at the Gateway and enriched with the tenant_id from the JWT. It is technically impossible for a request from Tenant A to access Tenant B's data — even in the event of an application bug. This partitioning is verified with every build via SAST/DAST scans.

Is our data used to train your AI models?

No. Your specifications, source code and production data are protected by Zero Data Retention (ZDR) contractual clauses with every AI provider used by WakaStart. Your intellectual property remains yours — it is never used to train any public or third-party model.

How are secrets and credentials managed?

All secrets (API keys, database credentials, authentication tokens) are stored in an encrypted Vault with Dev/Staging/Production isolation. No secret is ever hard-coded in the code — the SAST pipeline blocks any build containing a plaintext secret. Key rotation is automated. Developers never have access to production secrets.

What does NIS2 compliance actually involve?

The NIS2 directive (fully applicable since 2024) requires all B2B digital service providers to meet obligations including: documented risk management, a business continuity plan, incident notification within 24 hours, supply chain security and data encryption. WakaStart natively embeds all of these mechanisms — you can demonstrate NIS2 compliance to your enterprise clients from the moment your SaaS is delivered.

Does the digital vault have legal value in France?

Yes. WAKA-SEAL evidential archiving produces immutable archives with eIDAS 2.0-compliant qualified timestamping and blockchain-anchored SHA-256 cryptographic chaining. These archives are admissible as evidence before French and European courts. The one-click forensic report contains all the integrity evidence needed for an ISO 27001 audit or legal proceedings.

Is your SaaS
certifiable today?

Our free audit answers this question within 48 hours. Our CISO analyses your architecture, maps out non-compliance issues and provides you with a compliance roadmap with fixed timeline and budget. Free, confidential, no obligation.

Start my free audit See the infrastructure security →
ISO 27001-ready NIS2 native HDS eIDAS 2.0 GDPR WORM digital vault Post-quantum